easymultiple choiceObjective-mapped

Exhibit

Policy design notes:
- Scope: subscription
- Target: all resource groups
- Desired outcome: add tag CostCenter=042 automatically
- Requirement: do not block the deployment if the tag is omitted

Policy effects being considered:
- Deny
- Audit
- Append
- Modify

Based on the exhibit, a subscription policy must add CostCenter=042 to new resources, and deployments must not fail if the tag is missing. Which policy effect should you use?

Question 1easymultiple choice
Full question →

Based on the exhibit, a subscription policy must add CostCenter=042 to new resources, and deployments must not fail if the tag is missing. Which policy effect should you use?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Deny

Deny would block the deployment instead of allowing it to continue when the tag is missing.

B

Distractor review

Audit

Audit only records non-compliance and does not automatically add the missing tag.

C

Distractor review

Append

Append can add properties in some request scenarios, but it is not the best choice for automatic tag correction behavior.

D

Best answer

Modify

Modify is used to automatically change resource requests, such as adding or correcting tags, without blocking deployment.

Common exam trap

Common exam trap: ACLs stop at the first match

ACLs are processed top to bottom. The first matching entry wins, and an implicit deny usually exists at the end.

Technical deep dive

How to think about this question

ACL questions test precision: source, destination, protocol, port and direction. A generally correct ACL can still fail if it is applied on the wrong interface or in the wrong direction.

KKey Concepts to Remember

  • Standard ACLs match source addresses.
  • Extended ACLs can match source, destination, protocol and ports.
  • The first matching ACL entry is used.
  • There is usually an implicit deny at the end.

TExam Day Tips

  • Check inbound versus outbound direction.
  • Read the ACL from top to bottom.
  • Look for a broader permit or deny above the intended line.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

Standard ACLs match source addresses.

What is the correct answer to this question?

The correct answer is: Modify — The requirement is to keep deployments flowing while automatically adding the CostCenter tag. Modify is the policy effect designed to alter the request and apply the missing tag. That makes it more suitable than deny or audit because it enforces the standard without stopping the deployment. It is also the right choice when the goal is automatic correction rather than just reporting noncompliance. Why others are wrong: A blocks deployments and contradicts the requirement. B only reports the issue and leaves the tag missing. C is not the strongest fit for automatic tag correction in this scenario; the question asks for the effect that best matches ongoing remediation behavior.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.